Privacy Policy
Last Updated: 2 September 2026
This policy explains what Proof Chain does with your information, in plain terms and without overstating our privacy protections. It covers the Proof Chain iOS app and the website at proofapp.site.
1. Who we are
Proof Chain is operated by Mirsadra Molaei, an individual trading as Parkinsad ("Parkinsad", "we", "us", "our"). We are the data controller for the personal data described in this policy.
- Email: hi@proofapp.site
- Postal address: available on request by email
We are established in the United Kingdom, and this policy is written to meet the UK GDPR and the Data Protection Act 2018.
2. The short version
Proof Chain is built to collect as little as possible, but it is not a purely on-device app, and we will not claim that it is. The honest summary is:
- Customers do not create a named account. We never ask for your name, email address, phone number or payment details.
- Your device identifier does reach our server. Every check-in is verified server-side to stop fraudulent visits. That check sends your device identifier, so we can rate-limit and detect abuse.
- A business sees the visits made at that business. If you use an alias, a visit record is stored for the business you visited — never your name or contact details, and never your activity at any other business.
- Cloud backup is off unless you turn it on. Until you enable it, your visit history is stored only on your iPhone.
- We never sell or rent personal data, and we run no advertising or third-party tracking SDKs.
- Our servers are in the United States. See section 7.
3. What we collect from customers
A. Every time you check in
When you scan a business QR code and enter the verification word, your device contacts our server to confirm the visit is genuine before it is recorded. That request contains:
- A visit identifier and the business identifier
- The timestamp of the visit
- The verification word you entered and the cryptographic visit hash generated on your device
- Your device identifier — Apple's
identifierForVendor, which is specific to Proof Chain on your device and is reset if you delete the app - Your anonymous account identifier, if you have enabled cloud backup
We use this solely to verify the visit, enforce rate limits, and prevent forged or replayed check-ins. It is not used to build a profile of you and is not shared with any business in this raw form.
B. If you use an alias at a business
Choosing an alias (for example "COFFEELOVER") is what lets a business recognise your repeat visits and award loyalty rewards. If you set one, we store a visit record that the business you visited can see:
- The alias you chose
- The visit and business identifiers, the timestamp, the verification word and the visit hash
- A SHA-256 hash of your device identifier — not the identifier itself
- Your anonymous account identifier, if you have one
We also keep a customer identity record for that business containing the alias, the hashed device identifier, the date it was created and a visit count. An alias is pseudonymous: it does not contain your real identity, but it is still personal data under the UK GDPR, and we treat it as such.
If you do not set an alias, no visit record is stored for the business. The visit remains on your device only.
C. Optional cloud backup
Cloud backup is off by default. If you switch it on, the app creates an anonymous account for you — there is no email address, password or name attached to it — and copies your visit history and earned badges to our servers so you can restore them on a new device. You can delete that account and everything in it from within the app at any time.
D. Stored only on your device
Your full local visit history, your saved businesses and your scan attempts are held in the app's local database on your iPhone. If you have not enabled cloud backup, we cannot recover any of it if you lose or wipe your device.
4. What we collect from business owners
- Account: your email address and a user identifier, handled through Supabase authentication. If you sign in with Apple or Google, we receive the email address that provider releases to us and nothing more.
- Business profile: business name, address and approximate coordinates, category, QR code data and styling, verification words and their rotation history.
- Operational data: loyalty policies and reward tiers, reward claims, business settings, and staff access logs recording when a verification word was viewed.
- Subscription status: whether the Proof Chain Pro entitlement is active, via RevenueCat. We never see or hold your card details — Apple handles all payment.
5. Product analytics
We record a small number of anonymous product events — for example that a paywall was shown or a business was created — together with the app version. These events carry no user identifier, no device identifier and no alias, and cannot be traced back to you. We use no third-party analytics or advertising SDKs.
6. What we never collect
- GPS or precise location. A business address is entered by its owner; we do not track where you are.
- Advertising identifiers (IDFA), and we do not track you across other apps or websites.
- Your contacts, photo library, calendar, health data or microphone. The camera is used only to read a QR code, and those frames are never stored or transmitted.
- Payment card numbers or bank details.
7. Our lawful bases
Under Article 6 of the UK GDPR we rely on:
- Contract — to provide the service you asked for: recording your visits, running a business account, and delivering subscription features.
- Legitimate interests — to verify that check-ins are genuine, prevent fraud and abuse, keep the service secure, and understand aggregate product usage. We have balanced these against your rights and use the minimum data that works, including hashing the device identifier wherever a business can see it.
- Consent — for optional cloud backup and for push notifications, each of which you switch on yourself and can withdraw at any time.
- Legal obligation — where we must retain records to meet tax, accounting or legal requirements.
8. Who we share data with
We do not sell, rent or trade personal data, and we do not share it for advertising. We use a small number of processors who act on our instructions:
- Supabase — authentication, database and server-side functions. Hosted on Amazon Web Services.
- Apple — App Store distribution, all payment processing, and push notification delivery.
- RevenueCat — subscription entitlement management. It receives purchase receipts and an account identifier, not your payment details.
- GitHub — hosting for this website. It processes standard web server logs, including IP addresses, for security and delivery.
A business you visit can see the visit records made at that business, as described in section 3B. We may also disclose data where we are legally required to, or to establish or defend legal claims.
9. International transfers
Our Supabase database and server-side functions are hosted in the United States (AWS us-east-1). Apple and RevenueCat also process data outside the UK. This means personal data described in this policy is transferred out of the UK and the EEA.
These transfers are made under our data processing agreements with those providers, which incorporate the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum issued by the Information Commissioner. You may request a copy of the relevant safeguards by emailing hi@proofapp.site.
10. How long we keep it
- Visit records held for a business: kept until the business deletes them or closes its account, so that loyalty progress remains accurate.
- Cloud backups: kept until you delete your anonymous account or turn backup off, which removes them.
- Business accounts: kept while the account is active; deleted with the account, other than records we must keep for tax or legal reasons.
- Verification and fraud-prevention logs: kept only as long as needed to detect abuse patterns, then deleted.
- Local data on your device: kept until you delete it in the app or remove the app.
11. Security
- All traffic between the app and our servers is encrypted with TLS, and data is encrypted at rest by our hosting provider.
- Every database table is protected by row-level security, so a business account can reach only its own records.
- Visit proofs are generated on your device using an HMAC-SHA256 signature, which makes a visit record tamper-evident.
- Device identifiers are hashed with SHA-256 before being stored anywhere a business can read them.
No system is perfectly secure, but if a breach affects your rights we will notify the Information Commissioner's Office within 72 hours and tell you directly where the law requires it.
12. Your rights
You have the right to access your data, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time. In the app you can already:
- View your entire visit history, and export it as JSON or CSV
- Delete individual visits, or all local data
- Delete your anonymous backup account and everything stored under it
- As a business owner, edit your business details or delete your account and its data
For anything else, email hi@proofapp.site and we will respond within one month. Because customer data is pseudonymous by design, we may need you to supply the alias and business concerned so we can locate the right records; if we genuinely cannot identify you from the data we hold, we will tell you so.
13. Children
Proof Chain is not directed at children under 13, and business accounts require you to be 18 or over. We do not knowingly collect data from children. If you believe a child has provided personal data, email us and we will delete it.
14. Changes to this policy
We will update this policy when our practices change, and we will revise the date at the top. For changes that materially affect your rights we will give notice in the app before they take effect.
15. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the UK supervisory authority:
- Information Commissioner's Office — ico.org.uk/make-a-complaint, helpline 0303 123 1113
16. Contact
- Controller: Mirsadra Molaei, trading as Parkinsad
- Email: hi@proofapp.site
- Postal address: available on request
- Website: https://proofapp.site